Does traffic from Azure Firewall to Service Tag like Azure Monitor stays on backbone

RajivBansal-2486 271 Reputation points
2024-12-20T05:28:14.64+00:00

Hi,

I have hosted some containers in Azure which are sending telemetry to Application Insight. We have a firewall in the connectivity hub. All spoke traffic (0.0.0.0/0) is routed to the firewall. So the outbound traffic from container to Application insights will also get routed to firewall. I have two questions as under:

1.) It is guaranteed that the traffic from Azure Firewall to Azure resources like Application Insights remain on Azure Backbone?

2.) Is it better to route all the outbound traffic in spokes for Azure services to Firewall or should it be allowed to directly go the the services from spoke subnet itself without routing to Firewall (using User defined routes). If the traffic is routed to firewall will it provide any security benefit?

Thanks!

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
703 questions
{count} votes

Accepted answer
  1. Sai Prasanna Sinde 2,685 Reputation points Microsoft Vendor
    2024-12-20T08:44:18.9433333+00:00

    Hi @RajivBansal-2486,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    Answering to your 1st question: It is guaranteed that the traffic from Azure Firewall to Azure resources like Application Insights remain on Azure Backbone?

    • Yes, it is generally safe to assume that traffic from Azure Firewall to other Azure resources, such as Application Insights, will remain within the Azure backbone network. Microsoft has designed its network to ensure optimal performance and security within its ecosystem.

    But there are some exceptions:

    • While traffic is likely to stay within the Azure backbone, it might route through different regions to reach the Application Insights endpoint.
    • Some Azure services might have specific routing policies or dependencies that could influence the path.
    • Complex network setups with custom routing or third-party integrations could introduce external paths.

    Answering to your 2nd question: Is it better to route all the outbound traffic in spokes for Azure services to Firewall or should it be allowed to directly go the services from spoke subnet itself without routing to Firewall (using User defined routes). If the traffic is routed to firewall, will it provide any security benefit?

    It completely depends on your specific security needs and risk tolerance.

    But there are few disadvantages for Azure Firewall:

    Benefits of using Azure Firewall:

    Kindly let us know if the above helps or you need further assistance on this issue.

    Thanks,

    Sai.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.